Vulnerability Details CVE-2004-1669
Cross-site scripting (XSS) vulnerability in MERAK Mail Server 7.4.5 with Icewarp Web Mail 5.2.7 and possibly other versions allows remote attackers to execute arbitrary web script or HTML via the (1) User name parameter to accountsettings.html or (2) Search string parameter to search.html.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.3%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2004-1669
-
cpe:2.3:a:icewarp:web_mail:3.3.2
-
cpe:2.3:a:icewarp:web_mail:5.2.7
-
cpe:2.3:a:icewarp:web_mail:5.2.8
-
cpe:2.3:a:merak:mail_server:7.4.5